2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38487 | HIGH | 7 | 0.1% | Jun 16, 2026 | api-gateway container running with root privilege would allow an attacker to escape the container and access host system... |
| CVE-2024-30476 | MEDIUM | 5.4 | 0.2% | Jun 16, 2026 | PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote authenticated low-pr... |
| CVE-2024-24909 | HIGH | 8.8 | 0.4% | Jun 16, 2026 | Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the ga... |
| CVE-2024-22451 | MEDIUM | 6.7 | 0.1% | Jun 16, 2026 | Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An att... |
| CVE-2024-22447 | HIGH | 7.8 | 0.1% | Jun 16, 2026 | Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker... |
| CVE-2024-45636 | MEDIUM | 4.4 | 0.1% | Jun 11, 2026 | IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileg... |
| CVE-2024-32110 | MEDIUM | 4.3 | 0.1% | Jun 11, 2026 | Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This is... |
| CVE-2024-21944 | MEDIUM | 5.3 | 0.2% | Jun 10, 2026 | Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, r... |
| CVE-2024-58350 | MEDIUM | 4 | 0.1% | Jun 10, 2026 | Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initializati... |
| CVE-2024-56123 | — | — | — | Jun 8, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-56122 | — | — | — | Jun 8, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-56121 | — | — | — | Jun 8, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-56120 | — | — | — | Jun 8, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-58349 | CRITICAL | 9.8 | 0.7% | Jun 8, 2026 | WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers ... |
| CVE-2024-58348 | CRITICAL | 9.8 | 0.8% | Jun 8, 2026 | WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticate... |
| CVE-2024-27892 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been... |
| CVE-2024-27891 | MEDIUM | 6.9 | 0.3% | Jun 4, 2026 | On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies... |
| CVE-2024-27890 | CRITICAL | 9.6 | 4.4% | Jun 4, 2026 | Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been... |
| CVE-2024-6858 | MEDIUM | 6.5 | 0.1% | Jun 4, 2026 | In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there ... |
| CVE-2024-47273 | MEDIUM | 4.3 | 0.3% | Jun 3, 2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functiona... |
| CVE-2024-47263 | MEDIUM | 4.1 | 0.3% | Jun 3, 2026 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository web... |
| CVE-2024-14036 | HIGH | 8.7 | 0.3% | Jun 2, 2026 | Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-... |
| CVE-2024-42206 | LOW | 3.1 | 0.2% | Jun 2, 2026 | HCL iReflection Third party vulnerable and outdated components issue was detected in the web application |
| CVE-2024-52011 | HIGH | 8.3 | 0.5% | Jun 1, 2026 | launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the in... |
| CVE-2024-40646 | HIGH | 8.6 | 0.4% | Jun 1, 2026 | Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to co... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now